curl --request POST \
--url https://api.rach.finance/api/v1/giftcards/orders \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"reference": "<string>",
"product_id": 123,
"unit_price": "<string>",
"customer_id": "<string>",
"quantity": 1,
"recipient_email": "<string>",
"sender_name": "<string>",
"country_code": "<string>"
}
'import requests
url = "https://api.rach.finance/api/v1/giftcards/orders"
payload = {
"reference": "<string>",
"product_id": 123,
"unit_price": "<string>",
"customer_id": "<string>",
"quantity": 1,
"recipient_email": "<string>",
"sender_name": "<string>",
"country_code": "<string>"
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
reference: '<string>',
product_id: 123,
unit_price: '<string>',
customer_id: '<string>',
quantity: 1,
recipient_email: '<string>',
sender_name: '<string>',
country_code: '<string>'
})
};
fetch('https://api.rach.finance/api/v1/giftcards/orders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rach.finance/api/v1/giftcards/orders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'reference' => '<string>',
'product_id' => 123,
'unit_price' => '<string>',
'customer_id' => '<string>',
'quantity' => 1,
'recipient_email' => '<string>',
'sender_name' => '<string>',
'country_code' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.rach.finance/api/v1/giftcards/orders"
payload := strings.NewReader("{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.rach.finance/api/v1/giftcards/orders")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rach.finance/api/v1/giftcards/orders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}"
response = http.request(request)
puts response.read_bodyBuy a gift card
reference is your idempotency key and is required. Repeating a POST with the same
reference returns the ORIGINAL order rather than buying twice — enforced by a unique
index, so retrying after a timeout is always safe.
Order of operations, so a failure is never ambiguous:
- the request is validated against the real catalogue rules;
- your balance is debited atomically — too low stops here and nothing is spent;
- the provider float is checked — if it cannot cover the order you get a 503 and are not charged;
- the provider is called;
- if the provider fails, your balance is refunded automatically.
Execution is detached from this HTTP request: if your client times out the purchase still completes and is recorded. Never retry with a NEW reference after a timeout — look the order up by the original one.
On success the redeem code is fetched and attached to the order. It is returned
here and on GET /vas/orders/{reference}, but is deliberately NEVER included in a
webhook — it is a bearer secret that anyone holding can spend.
curl --request POST \
--url https://api.rach.finance/api/v1/giftcards/orders \
--header 'Content-Type: application/json' \
--header 'X-API-Key: <api-key>' \
--data '
{
"reference": "<string>",
"product_id": 123,
"unit_price": "<string>",
"customer_id": "<string>",
"quantity": 1,
"recipient_email": "<string>",
"sender_name": "<string>",
"country_code": "<string>"
}
'import requests
url = "https://api.rach.finance/api/v1/giftcards/orders"
payload = {
"reference": "<string>",
"product_id": 123,
"unit_price": "<string>",
"customer_id": "<string>",
"quantity": 1,
"recipient_email": "<string>",
"sender_name": "<string>",
"country_code": "<string>"
}
headers = {
"X-API-Key": "<api-key>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'X-API-Key': '<api-key>', 'Content-Type': 'application/json'},
body: JSON.stringify({
reference: '<string>',
product_id: 123,
unit_price: '<string>',
customer_id: '<string>',
quantity: 1,
recipient_email: '<string>',
sender_name: '<string>',
country_code: '<string>'
})
};
fetch('https://api.rach.finance/api/v1/giftcards/orders', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.rach.finance/api/v1/giftcards/orders",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'reference' => '<string>',
'product_id' => 123,
'unit_price' => '<string>',
'customer_id' => '<string>',
'quantity' => 1,
'recipient_email' => '<string>',
'sender_name' => '<string>',
'country_code' => '<string>'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json",
"X-API-Key: <api-key>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.rach.finance/api/v1/giftcards/orders"
payload := strings.NewReader("{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("X-API-Key", "<api-key>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.rach.finance/api/v1/giftcards/orders")
.header("X-API-Key", "<api-key>")
.header("Content-Type", "application/json")
.body("{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.rach.finance/api/v1/giftcards/orders")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["X-API-Key"] = '<api-key>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"reference\": \"<string>\",\n \"product_id\": 123,\n \"unit_price\": \"<string>\",\n \"customer_id\": \"<string>\",\n \"quantity\": 1,\n \"recipient_email\": \"<string>\",\n \"sender_name\": \"<string>\",\n \"country_code\": \"<string>\"\n}"
response = http.request(request)
puts response.read_bodyAuthorizations
Business API key for server-to-server integrations.
Key prefix determines the environment — no separate flag needed:
test_sk_* = sandbox/testnet, live_sk_* = production/mainnet.
Body
Response
Order placed

